--- parser3/src/classes/op.C 2009/05/05 10:06:57 1.186 +++ parser3/src/classes/op.C 2009/07/14 11:14:34 1.194 @@ -5,7 +5,7 @@ Author: Alexandr Petrosian (http://paf.design.ru) */ -static const char * const IDENT_OP_C="$Date: 2009/05/05 10:06:57 $"; +static const char * const IDENT_OP_C="$Date: 2009/07/14 11:14:34 $"; #include "classes.h" #include "pa_vmethod_frame.h" @@ -70,7 +70,7 @@ static const String exception_var_name(E // helpers -class Untaint_lang_name2enum: public Hash { +class Untaint_lang_name2enum: public HashString { public: Untaint_lang_name2enum() { #define ULN(name, LANG) \ @@ -88,6 +88,7 @@ public: ULN("html", HTML); ULN("optimized-html", HTML|String::L_OPTIMIZE_BIT); ULN("regex", REGEX); + ULN("parser-code", PARSER_CODE); #undef ULN } } untaint_lang_name2enum; @@ -123,7 +124,8 @@ static void _untaint(Request& r, MethodP Value& vbody=params.as_junction(params.count()-1, "body must be code"); Temp_lang temp_lang(r, lang); // set temporarily specified ^untaint[language; - r.write_pass_lang(r.process(vbody)); // process marking tainted with that lang + StringOrValue result=r.process(vbody); // process marking tainted with that lang + r.write_assign_lang(result); } } @@ -137,11 +139,8 @@ static void _taint(Request& r, MethodPar { Value& vbody=params.as_no_junction(params.count()-1, "body must not be code"); - String result; - result.append( - vbody.as_string(), // process marking tainted with that lang - lang, true); // force result language to specified - r.write_pass_lang(result); + String result(vbody.as_string(), lang); // force result language to specified + r.write_assign_lang(result); } } @@ -165,7 +164,7 @@ static void _process(Request& r, MethodP "no target class"); // temporary remove language change - Temp_lang temp_lang(r, String::L_PASS_APPENDED); + Temp_lang temp_lang(r, String::L_PARSER_CODE); // temporary zero @main so to maybe-replace it in processed code Temp_method temp_method_main(*target_class, main_method_name, 0); // temporary zero @auto so it wouldn't be auto-called in Request::use_buf @@ -214,7 +213,7 @@ static void _process(Request& r, MethodP // evaluate source to process const String& source=r.process_to_string(vjunction); r.use_buf(*target_class, - source.cstr(String::L_UNSPECIFIED, r.connection(false)), + source.untaint_cstr(String::L_AS_IS, r.connection(false)), main_alias, processe_file_no, line_no_alias_offset); @@ -421,7 +420,7 @@ r.sql_connect_time+=t[1]-t[0]; Temp_connection temp_connection(r, connection); // execute body try { - r.write_assign_lang(r.process(body_code)); + r.process_write(body_code); connection->commit(); connection->close(); } catch(...) { // process problem @@ -898,11 +897,11 @@ VClassMAIN::VClassMAIN(): VClass() { // ^if(condition){code-when-true}{code-when-false} add_native_method("if", Method::CT_ANY, _if, 2, 3, Method::CO_WITHOUT_FRAME); - // ^untaint[as-is|uri|sql|js|html|html-typo|regex]{code} - add_native_method("untaint", Method::CT_ANY, _untaint, 1, 2, Method::CO_NONE); + // ^untaint[as-is|uri|sql|js|html|html-typo|regex|parser-code]{code} + add_native_method("untaint", Method::CT_ANY, _untaint, 1, 2, Method::CO_WITHOUT_FRAME); - // ^taint[as-is|uri|sql|js|html|html-typo|regex]{code} - add_native_method("taint", Method::CT_ANY, _taint, 1, 2, Method::CO_NONE); + // ^taint[as-is|uri|sql|js|html|html-typo|regex|parser-code]{code} + add_native_method("taint", Method::CT_ANY, _taint, 1, 2, Method::CO_WITHOUT_FRAME); // ^process[code] add_native_method("process", Method::CT_ANY, _process, 1, 3);